High severity7.5NVD Advisory· Published Aug 29, 2023· Updated Jun 17, 2026
CVE-2023-39663
CVE-2023-39663
Description
Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mathjaxnpm | <= 2.7.9 | — |
Affected products
5- Mathjax/Mathjaxdescription
- osv-coords3 versions
< 0+ 2 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: <= 2.7.9
Patches
Vulnerability mechanics
References
3- github.com/mathjax/MathJax/issues/3074nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-v638-q856-grg8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-39663ghsaADVISORY
News mentions
0No linked articles in our index yet.